P1 Security @p1security.bsky.social · 08/10/2026QCSuper has a sequel: DiagNG, a new GUI-based open source tool for Linux producing PCAP/GSMTAP captures from Qualcomm Snapdragon basebands for Wireshark, NR/5G included. Blog: www.p1sec.com/blog/present... Code: github.com/P1sec/DiagNG 010
P1 Security @p1security.bsky.social · 01/10/2026P1 Security will be at India Mobile Congress 2026, 7 to 10 October, Yashobhoomi, New Delhi. Want to talk signalling, interconnect or 5G core security? Book a slot with our team: www.p1sec.com/contact #IMC2026 #TelecomSecurity 000
P1 Security @p1security.bsky.social · 29/09/2026The AMF trusts the device (N1), the gNB (N2) and the 5G core (SBI) in three different ways. Our AMF Under Pressure replay walks the attack paths on each. watch.getcontrast.io/register/p1-se… 001
P1 Security @p1security.bsky.social · 24/09/2026Most O-RAN interface protections are mandatory to support and optional to enable. The gap between supported and switched on is a fixable deployment question. New O-RAN security whitepaper: www.p1sec.com/white-paper/o-ran-sec… #ORAN #TelecomSecurity 010
P1 Security @p1security.bsky.social · 22/09/2026A pentest describes your network on the day it was tested. Mobile networks keep changing: new elements, new interconnects, new releases, configuration drift. Assessment belongs on a cycle, paired with continuous visibility. www.p1sec.com/ugtmns #TelecomSecurity 000
P1 Security @p1security.bsky.social · 17/09/2026Interconnect filtering decides which messages may reach the HLR or HSS. It says nothing about how the element answers a malformed one. Our research on assessing the subscriber database itself: www.p1sec.com/white-paper/hacking-t… #TelecomSecurity 010
P1 Security @p1security.bsky.social · 15/09/2026191 articles on mobile network security, filed into 14 chapters. SS7 and Diameter through 5G SBA, O-RAN, IMS, roaming, detection and regulation. Enter by attack surface, by role, or by generation. No gate, no form, no download. www.p1sec.com/ugtmns 010
P1 Security @p1security.bsky.social · 14/09/2026Tomorrow, live with Titan.ium: Offense vs Defense in Telecom Security. What a network hands over to a stranger, and the firewall rule that stops it. Built live on screen. 15 Sept, 16:00 CEST. titaniumplatform.com/webinar-offe... 010
P1 Security @p1security.bsky.social · 10/09/2026A CVE feed says a vulnerability exists. It does not say what it does inside a mobile network. The P1 VKB: 2,200+ telecom vulnerabilities from SS7 to 5G, with impact and remediation context. www.p1sec.com/product/vulnerability… #TelecomSecurity 010
P1 Security @p1security.bsky.social · 08/09/202611 September 2026: the CRA reporting clock starts. Actively exploited vulnerabilities in products with digital elements, early warning in 24 hours. Telecom equipment included. www.p1sec.com/services/supply-chain… #TelecomSecurity 000
P1 Security @p1security.bsky.social · 21/08/2026The most damaging findings in 5G core pentests are rarely exotic: default credentials, reused root SSH keys, SSRF that turns the SCP into an internal scanner. New whitepaper on the five classes we find most. www.p1sec.com/white-paper/... #5G #TelecomSecurity 011
P1 Security @p1security.bsky.social · 17/08/2026P1 Security is at LEAP 2026 in Riyadh, 31 August to 3 September. Vikas Sharma is there taking meetings on what the signalling layer exposes: SS7, Diameter, GTP, IMS, 5G core, RAN. contact@p1sec.com 000
P1 Security @p1security.bsky.social · 28/07/2026Ask an operator where its attack surface is and the answer depends who is in the room: SS7, GTP, IMS, RAN. TelcoASM puts them in one matrix so you can see where exposure concentrates. Self-assessment, no scan. telcoasm.p1sec.com #TelecomSecurity 000
P1 Security @p1security.bsky.social · 23/07/2026Smishing isn't an inbox problem. The fraud lives in signalling: origins spoofed over SS7, A2P grey routes past the SMSC. Content filters can't see that. www.p1sec.com/blog/sms-based-attack… #SS7 #Smishing 000
P1 Security @p1security.bsky.social · 22/07/2026Three ways into the AMF, each trusting a different neighbour: N1 (device/NAS), N2 (radio/NGAP), SBI (peer NFs/HTTP2). Free webinar, Wed 29 Jul 15:00 CET: watch.getcontrast.io/register/p1-se… 010
P1 Security @p1security.bsky.social · 21/07/2026EECC, NIS2, ENISA, the EU 5G Toolbox: Europe's telecom security rules overlap and evolve. Our whitepaper maps how they fit together, for operators and regulators. www.p1sec.com/white-paper/towards-h… #NIS2 #Compliance 000
P1 Security @p1security.bsky.social · 16/07/2026Deploy private 5G/4G or CBRS and you're now a mobile network operator: a core, RAN, SIMs and signaling to defend, often with no telecom security team. Slice isolation and exposed OAM are risks IT scanners miss. www.p1sec.com/services/private-5g-s… 001
P1 Security @p1security.bsky.social · 15/07/20265G standalone's core speaks HTTP/2, JSON and REST APIs over the SBI, not SS7 or Diameter. So it inherits web-app risk: broken authZ between NFs, broad tokens, injection, weak TLS. An API problem, not just signaling. securityhub.p1sec.com/guide 000
P1 Security @p1security.bsky.social · 09/07/2026Telecom security training is easier to judge when someone walks you through it. Want a live look at P1 Academy (SS7 to 5G, hands-on labs)? We will give you a 30-min walkthrough. Email contact@p1sec.com or see online-training.p1sec.com #Training 000
P1 Security @p1security.bsky.social · 07/07/2026Voice runs on SIP now. VoLTE, VoWiFi and VoNR inherit IP-style risks: spoofing, malformed messages, weak transport. SBCs miss it. Why SIP IDS matters: www.p1sec.com/blog/international-ip… #TelecomSecurity #IMS 000
P1 Security @p1security.bsky.social · 01/07/2026Your firewall sees packets, not a MAP operation or a Diameter command, so signalling attacks, fraud and GTP-C misuse slip through for months. Telecom IDS is the missing layer. How PTM catches what firewalls miss: www.p1sec.com/product/intrusion-det… 000
P1 Security @p1security.bsky.social · 01/07/2026GTP-C sets up sessions, GTP-U carries the data, and both cross the same roaming links. That trust gets abused for DoS, overbilling and data disclosure. Common GTP attacks and defences: www.p1sec.com/blog/common-attacks-o… 000
P1 Security @p1security.bsky.social · 30/06/2026Thank you to CSAI, TEMA & CMAI for hosting the National Conference on Telecom Security in the AI & Quantum Age (25 June, IIC New Delhi), and to everyone we met for the conversations on AI-era and post-quantum telecom security. #TelecomSecurity 000
P1 Security @p1security.bsky.social · 12/05/2026Cloud RAN is changing the RAN attack surface. Tomorrow, we unpack the new threats across fronthaul, F1/E1, OAM, virtualisation and monitoring. Final chance to register: watch.getcontrast.io/register/p1-...watch.getcontrast.ioCloud RAN security: Exploring new threatsCloud RAN is changing the structure of mobile networks and introducing new security questions that operators and security teams cannot ignore. As radio acc... 000
P1 Security @p1security.bsky.social · 07/05/2026One malformed signaling message can crash core functions that are not directly exposed. Our latest write-up shows how stateful fuzzing exposes AMF, SMF, and MME crash paths across 5G and 4G. Proprietary does not mean fuzz tested. www.p1sec.com/blog/fuzzing...p1sec.com5G and 4G Core Fuzzing: How Malformed Signaling Can Crash Mobile NetworksFrom corner-case parser bugs in open-source cores to systemic risks in commercial-grade 5G deployments. 120
P1 Security @p1security.bsky.social · 15/04/2026APTs target telecom cores for tracking & intel. Recording: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity 000
P1 Security @p1security.bsky.social · 14/04/2026Open source drives telecom innovation. It also needs real protocol security testing. Our latest Ella Core findings are on cve.p1sec.com #TelecomSecurity #OpenSourceSecuritycve.p1sec.comSecurity Advisories & CVEs | P1 Security - Telecom & 5G CybersecurityExplore P1 Security's published CVEs, Open-Source project security contributions, and Coordinated Vulnerability Disclosures (CVD). We are the world leader in Telecom, 5G, and SS7 security. 000
P1 Security @p1security.bsky.social · 08/04/2026Cyber conflict has a long memory. In this clip, Hamid Kashfi touches on how methods evolve and resurface over time. Replay: watch.getcontrast.io/register/p1-... #telcosec #telecomsecurity 010
P1 Security @p1security.bsky.social · 02/04/2026Where are we actually exposed? TelcoASM helps telecom teams quickly visualize network risk exposure and benchmark it in minutes. Free: telcoasm.p1sec.com 000
P1 Security @p1security.bsky.social · 01/04/2026At a radio site, they feared metal theft. The bigger risk was RAN to core compromise. Watch: watch.getcontrast.io/register/p1-security-physical-to-5g-core-compromise 010
P1 Security @p1security.bsky.social · 23/03/2026Join us for TelcoSec Talk #2, with Philippe Langlois and Hamid Kashfi as we map the Iran-linked APT ecosystem. We’re connecting technical signals and infrastructure to see the full picture. Tomorrow 11am CET. 🛡️ Register: watch.getcontrast.io/register/p1-... #CyberSecurity #APT #ThreatIntel #warwatch.getcontrast.ioTelcoSec Talk #2 Decoding the Iran CyberAttacks & APT Landscape: Both victims and attackersThis session explores the Iran APT and cyber threat landscape from 2007 to 2026 through a telecom security lens. We will analyze how signaling layer activi... 000
P1 Security @p1security.bsky.social · 18/03/2026Next week: TelcoSec Talk #2 with Philippe Langlois and Hamid Kashfi on the Iran cyber threat landscape, using ApexThreats. Register: watch.getcontrast.io/register/p1-... #CyberThreatIntelligence #TelecomSecurity #ThreatIntelligence #CyberSecurity #APT #Iran #TelcoSec #P1Security 000
P1 Security @p1security.bsky.social · 11/03/2026MWC is done. The badge is off. The conversations are not. What stood out most? Telecom security is a real operational priority. If we missed you at MWC, let’s continue the discussion: contact@p1sec.com #MWC26 #TelecomSecurity #5GSecurity #CyberSecurity #P1Security 000
P1 Security @p1security.bsky.social · 03/03/2026P1 Security will be part of the Online [un]prompted conference this week. Philippe Langlois, our founder and CEO, will moderate a lunchtime Zoom chat session titled: Defense and Offense of Critical Infrastructure in the Age of AI Contact: contact@p1sec.com #AISecurity 010
P1 Security @p1security.bsky.social · 26/02/2026“Open it temporarily so it works” is how 5G networks get permanently exposed. “No firewall matrix, no traffic flow visibility, so people open the network until things work… then leave it like it is.” Recording: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity #ZeroTrust 010
P1 Security @p1security.bsky.social · 12/02/2026SMS blasters = high volume spam or fraud. At #MWC2026 in Barcelona, we’re bringing a fun SMS Blaster Detector experiment. Let’s meet: www.p1sec.com/mwc-2026 110
P1 Security @p1security.bsky.social · 03/02/2026Physical access is not “local only”. In many environments it can become a network foothold, then pivot via the management plane, weak segmentation, insecure remote access, or stolen creds until the 5G core is reachable. Register: watch.getcontrast.io/register/p1-... 000
P1 Security @p1security.bsky.social · 20/01/2026How does physical exposure translate into risk for mobile critical infrastructure, and how can teams reduce it without slowing operations down? Physical to 5G Core Compromise Red team lessons learned + practical takeaways Thu 5 Feb 2026, 14:00 CET Register: watch.getcontrast.io/register/p1-... 000
P1 Security @p1security.bsky.social · 04/12/2025We released the Telco Attack Surface Matrix to help teams visualise exposure across RAN, Core, IMS, signalling and more. Try it and share your feedback so we can improve it. telcoasm.p1sec.com #telcosec 000
P1 Security @p1security.bsky.social · 13/11/2025Weak passwords still break 5G in 2025. No zero days needed. If your access controls rely on bad defaults, start fixing them. Replay 👉 watch.getcontrast.io/register/p1-... 000
P1 Security @p1security.bsky.social · 29/10/2025In 5G, you don’t lose the network when someone gets in you lose it when you realize there was never proper control in the first place. Full replay: watch.getcontrast.io/register/p1-... #5GSecurity #TelecomSecurity #CoreNetworkSecurity #5GPentest 010
P1 Security @p1security.bsky.social · 24/10/2025Wednesday we held our webinar “Top 5G Security Vulnerabilities: Insights from P1 Security Pentest Activities.” Thanks for joining. As promised, here’s the recording — watch and share with your team: watch.getcontrast.io/register/p1-... #5GSecurity #Cybersecurity #Telecom 030
P1 Security @p1security.bsky.social · 14/10/2025LTE’s All-IP design expands the attack surface—legacy SS7 meets Diameter, S1, X2 & GTP risks. Read real flaws & mitigations in the *LTE Pwnage* ebook: www.p1sec.com/white-paper/... #LTE #CyberSecurity #P1Security 010
P1 Security @p1security.bsky.social · 09/10/2025Everyone talks about resilience. We focus on the foundation. Strong passwords mean nothing if your 5G core is exploitable. Join 5G Penetration Tester El Mehdi Regragui as he reveals real pentest findings across signaling & OAM. 🔗 watch.getcontrast.io/register/p1-... #5GSecurity 000
P1 Security @p1security.bsky.social · 23/09/2025🌏 Our Global Account Manager, Thilip Suppaiah, is at #DNSKualaLumpur representing P1 Security. Attending? Reach out: contact@p1sec.com #DigitalNationSummit #GSMA 000
P1 Security @p1security.bsky.social · 10/09/2025Top 5G Security Vulnerabilities revealed 🔓 Weak auth, misconfigured cores & more, 5G still opens doors for attackers. Join P1 Security’s El Mehdi Regragui as he shares exclusive pentest insights watch.getcontrast.io/register/p1-... #5G #TelecomSecurity #Pentesting #MobileSecurity #Webinarwatch.getcontrast.ioTop 5G Security Vulnerabilities: Insights from P1 Security Pentest ActivitiesJoin El Mehdi Regragui as he reveals the most critical 5G security vulnerabilities uncovered in real-world penetration tests—plus proven mitigation tactics... 010
P1 Security @p1security.bsky.social · 27/08/20255G was built to be “secure by design.” In practice, many deployments still expose Diameter, GTP & SBA interfaces attackers can abuse. Full replay 👉 watch.getcontrast.io/register/p1-... Is your network secure in practice? Book a call 👉 calendly.com/yves-mangamb... #5G #TelecomSecurity #P1Security 000
P1 Security @p1security.bsky.social · 20/08/2025📡 5G: More Features, More Attack Surfaces SBA, slicing, NFV, HTTP/2 APIs… 5G isn’t just faster, it’s more complex (attackers love complex). Learn to secure it with TS-501: 5G Telecom Security ⬇️ online-training.p1sec.com/course/5g-te... #5G #TelecomSecurity #TS501online-training.p1sec.com5G Telecom Security hands-on course (TS-501)This virtual training will help security and telecom professionals get an understanding of the key concepts of 5G, their security, the implementation of such architectures and the impact in terms of r... 010
P1 Security @p1security.bsky.social · 14/08/2025🛡️ From SS7 flaws to the latest HTTP/2 5G zero-days, P1 Security’s VKB tracks them all. ⚡ Always up-to-date ⚡ Telecom-native context ⚡ Actionable before attackers strike 🔗 saas.p1sec.com/home www.p1sec.com/product/vuln... #TelecomSecurity #VKB #5G #HTTP2 #SignalingSecurity 010
P1 Security @p1security.bsky.social · 06/08/2025📡 IMS & SIP: Core to telecom — and top targets for attackers. ⚠️ SIP spoofing, session hijacking ⚠️ IMS DoS, weak auth, 3rd-party app risks 🔍 Learn how they work, where they break, and how to secure them: www.p1sec.com/blog/ims-and... #TelecomSecurity #IMS #SIPp1sec.comIMS and SIP Protocol: Enhancing Security in Prepaid and Postpaid Telecom SystemsIMS and SIP Protocol: Enhancing Security in Prepaid and Postpaid Telecom Systems 000